Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 326

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
These stocks have momentum on their side heading into earnings, including Amazon
From Silicon Valley to DC, the tech world is suddenly obsessed with one concept in AI: Distillation
UPS expects third-quarter domestic revenue to be flat but CEO tells CNBC the company is through its 'bumps'
BofA thinks ASML isn’t under threat from China, and that investors are overreacting
Analysis: Kevin Warsh has three reasons to hold off on a Fed rate hike this week
Student loan default is rising: 3 ways to start paying down your balance — even on a tight budget
New Republican ads slam Democrats opposed to Trump's tariffs
Boeing posts wider loss than expected as Air Force One costs weigh on results
Apple plans to lease iPhones for $17.99 a month through partnership with Klarna
Movie: Forbidden Fruits